Latvian Road Traffic Agency Suffers Major Data Breach, Officials Face Calls for Resignation
Latvia's **Road Traffic Safety Directorate (CSDD)** has confirmed a significant cyberattack resulting in the theft of data impacting roughly two-thirds of the country's population. The breach, which accessed payment receipt data dating back to 2008, has sparked a political controversy and led to calls for the resignation of senior officials.
Latvia's **Road Traffic Safety Directorate (CSDD)** has disclosed a major cyberattack that compromised the personal data of over 1.2 million individuals and 200,000 businesses. The breach, affecting approximately two-thirds of Latvia's population, has led to intense scrutiny and the resignation of the agency's supervisory board.
### Scope of the Breach
The **CSDD**, the state agency responsible for vehicle registration and driver's licenses, confirmed that hackers gained access to payment receipt data stretching back to 2008. The stolen information includes personal identification numbers, company registration numbers, vehicle license plate numbers, payment amounts and dates, and addresses from vehicle registration certificates.
While sensitive data such as customer phone numbers, email addresses, usernames, and passwords were reportedly not compromised, **CERT.LV**, Latvia's computer emergency response team, has warned that the exfiltrated information could be leveraged for social engineering and fraud schemes.
Despite the severity of the breach, **CSDD** stated that its day-to-day operations, including online and in-person services, remained uninterrupted. The agency also reported successfully blocking a subsequent cyberattack attempt following security enhancements implemented after the initial incident.
### A Complex and Targeted Attack
The **CSDD** initially described the incident as a "complex" cyberattack, indicating that third parties achieved partial access to systems containing historical payment receipt data. **Varis Teivans**, deputy head of **CERT.LV**, noted that "the attack was targeted and that prior preparation was made for its implementation," further adding that "the nature of the attack and the set of methods used also indicate the technical competence of the attackers."
**CERT.LV** later revealed that the hackers exploited a vulnerability in a **CSDD** system exposed to the internet, and that several mandatory cybersecurity requirements had not been met by the agency.
### Political Fallout and Resignations
The cyberattack has quickly escalated into a political issue, with **President Edgars Rinkevics** declaring it a "significant threat to national security." President Rinkevics publicly called for the resignation of **CSDD**'s leadership, stating, "The CSDD's reputation and public trust in this institution have been undermined." This sentiment was echoed by Latvian member of Parliament **Andris Kulbergs**.
In response to the mounting pressure, the **CSDD**'s supervisory board submitted its resignation. **CSDD** chief **Aivars Aksenoks** has also announced his intention to step down after assisting with the investigation and addressing the aftermath of the attack.
### Shifting Blame and Ongoing Investigations
**Aksenoks** has suggested that responsibility for the breach may not rest solely with **CSDD**, pointing to **Tet**, a Latvian telecom and technology company that provides some of the agency's IT infrastructure and security monitoring. According to **Aksenoks**, **Tet** failed to detect the intrusion or alert the agency, with **CSDD** employees discovering and stopping the attack themselves.
**Tet**, however, has pushed back against premature blame, with chairman **Uldis Tatarcuks** emphasizing the need for a thorough investigation to determine how and when attackers gained access, which systems were compromised, and where security measures failed. **Tet** also clarified that its responsibilities cover specific parts of **CSDD**'s IT infrastructure, not the agency's entire network.
Latvian cybersecurity and data protection authorities are continuing their investigations, and state police have initiated criminal proceedings. This incident follows another notable cyberattack in June against the state-owned forestry company **LVM**, which also impacted critical systems.